Re: Snort & email

From: Joel Esler (eslerj_at_gmail.com)
Date: 05/07/05

  • Next message: James Riden: "Re: Snort & email"
    Date: Sat, 7 May 2005 17:14:09 -0400
    To: "Dan S Baxter" <Dan.Baxter@ipaper.com>
    
    

    Swatch. google it up..

    On May 4, 2005, at 11:16 AM, Dan S Baxter wrote:

    >
    > I'm setting up a Snort sensor in our environment and I am unable to
    > determine how I might get emailed on alerts. I understand some are
    > using
    > Swatch, but we are not logging to syslogs but rather to a mysql db.
    > What
    > are others doing in this case?
    >
    > If I can't get it to alert me, it doesn't do me as much good, as I do
    > not
    > have the time to watch it 24/7.
    >
    > Dan Baxter
    > International Paper
    > Information Risk Management
    > 901-419-5193
    >
    >
    >
    > -----------------------------------------------------------------------
    > ---
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it with real-world attacks from
    > CORE IMPACT.
    > Go to
    > http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    > to learn more.
    > -----------------------------------------------------------------------
    > ---
    >

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: James Riden: "Re: Snort & email"

    Relevant Pages

    • Re: Snort rules setup.
      ... If you don't want to see them at all, suppress them. ... they are alerts of an Open Port Detection through the sfportscan preprocessor. ... Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • Re: IDS event filtering
      ... you can defenitively disable IDS alerts for software which you don't have ... administrators tend to ignore them which will render your IDS ineffective. ... Find out quickly and easily by testing it with real-world attacks from ... CORE IMPACT. ...
      (Focus-IDS)
    • Re: auto-response IDS againt port-scanning or attacked ip?
      ... That shows you how to setup Swatch to email you alerts ... > So is there any free IDS console which supports this function? ... > (Automatically e-mail alram to attcking ip) ... Find out by easily testing it with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • Re: Snort & email
      ... > Swatch, but we are not logging to syslogs but rather to a mysql db. ... snort generates way too many alerts to email/page ... Typically I'd only be using paging for attempted-admin ...
      (Focus-IDS)